DefectDojo’s cover photo
DefectDojo

DefectDojo

Computer and Network Security

Austin, Texas 2,646 followers

DefectDojo is the open source vulnerability management platform that remediates at the speed of AI

About us

DefectDojo is the open source unified vulnerability management platform that remediates at the speed of AI. Built by practitioners to end security finding sprawl, DefectDojo aggregates findings from more than 500 security tools into a single system of action, then automatically deduplicates, enriches, and prioritizes them so teams remediate real risk instead of drowning in noise. Sensei, DefectDojo's AI, closes the loop from detection to remediation by scanning repositories and opening pull requests that fix vulnerabilities without leaving the platform. Security teams use DefectDojo to automate triage, enforce SLAs, and report on security posture and compliance across frameworks including SOC 2, PCI-DSS, and the EU Cyber Resilience Act. Born from the OWASP community, DefectDojo is trusted by organizations of every size, from individual practitioners running the free Community Edition to enterprises deploying DefectDojo Pro in the cloud, on-premises, or in air-gapped environments. Learn more at defectdojo.com.

Website
https://www.defectdojo.com
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Austin, Texas
Type
Privately Held
Founded
2014
Specialties
cybersecurity, vulnerability correlation, devsecops, vulnerability management, and ASPM

Products

Employees at DefectDojo

View 26 employees at DefectDojo

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

See all employees

Locations

  • Primary

    1515 E Cesar Chavez St

    Suite 100 PMB 1061

    Austin, Texas 78702, US

    Get directions

Updates

  • View organization page for DefectDojo

    2,646 followers

    DefectDojo October 6th Changelog 🚀 This week, we've released a new update of DefectDojo Pro and Community Edition. Here are the highlights from v3.4.0. * 🧪 (Sandbox) - Sandbox Mode: a practice copy of DefectDojo Pro under /sandbox/, on its own database and preloaded with sample data, with Reset and Wipe for superusers. Nothing done in the sandbox reaches production. * 🤖 (AI Inventory) - A beta AI inventory: every scanned repository gets an inventory of its coding assistants, MCP servers, models, AI packages, AI service endpoints, agent skills, and provider keys. * 🔌 (Connectors) - New Microsoft Azure and Google Cloud asset connectors, and a new Kenna Security (Cisco Vulnerability Management) connector. * and much more! Check out the changelog here: https://bit.ly/47zB5eS

  • Claude's advanced cyber capabilities are locked for almost everyone. Anthropic just unlocked them for DefectDojo, and we're pointing them at defense. That means exploit development, red teaming, penetration testing and bug bounty work. Claude blocks that category by default, for everyone. After its Cyber Verification Program review, Anthropic turned it on for our team. Why it matters: AI is finding zero-days in every major OS and browser. Attackers will have that, and nobody vets them. Defenders were getting told no by their own AI halfway through proving a finding is real. Why us: open any DefectDojo test file and it reads like an attacker's notebook, because that's what 500+ scanners send us every day. Plenty of vendors say they work for defenders. Anthropic checked who we are and what we do, and verified it. The access is monitored and can be pulled the day we drift. We'd rather be held to account than handed a badge. Fight AI with AI. Our team just got cleared for the advanced stuff. Full story: https://lnkd.in/g_zZRgzP

    • Blog cover with the title Anthropic Unlocks Claude's Advanced Cyber Capabilities for DefectDojo, in orange text on a tan card tilted over a graph-paper grid, with the label Security.
  • DefectDojo reposted this

    Claude's advanced cyber capabilities are locked for almost everyone. Anthropic just unlocked them for DefectDojo, and we're pointing them at defense. That means exploit development, red teaming, penetration testing and bug bounty work. Claude blocks that category by default, for everyone. After its Cyber Verification Program review, Anthropic turned it on for our team. Why it matters: AI is finding zero-days in every major OS and browser. Attackers will have that, and nobody vets them. Defenders were getting told no by their own AI halfway through proving a finding is real. Why us: open any DefectDojo test file and it reads like an attacker's notebook, because that's what 500+ scanners send us every day. Plenty of vendors say they work for defenders. Anthropic checked who we are and what we do, and verified it. The access is monitored and can be pulled the day we drift. We'd rather be held to account than handed a badge. Fight AI with AI. Our team just got cleared for the advanced stuff.

    • No alternative text description for this image
  • Every scanner tells you what's wrong. None of them decide what happens next. So a person does it. Review the Finding, judge the risk, find the owner, notify them, open the ticket, track it. Then do it again for the next thousand. With DefectDojo Pro, your team writes that decision down once. Triage Engine turns the rules you already follow into workflows that run on every Finding. Critical Findings get an owner, a Slack message, and a Jira ticket. Lower-severity Findings get tagged for weekly review. You can see everything the automation does. Simulation runs a Rule against real Findings without sending anything outside DefectDojo. Every Run is traced node by node, so if 400 Findings enter a filter and zero pass, you see where. Each Finding shows which Rule changed it. Rules make the routine calls so your team can make the hard ones. Read the post: https://bit.ly/4hqRu9V #DefectDojo #vulnerabilitymanagement #AppSec

  • DefectDojo September 29th Changelog 🚀 This week, we've released a new update of DefectDojo Pro and Community Edition. Here are the highlights from v3.3.300. * 🌐 (i18n) - The Pro UI is now multilingual, with 27 languages available including German, Japanese, French, Italian, Spanish, Dutch, Portuguese (Brazil), Russian, Hindi, Bengali, Marathi, Tamil, Telugu, Hebrew, Arabic, Persian, and Urdu. A new setting lets you choose the interface language. * 📍 (Locations) - Code to Cloud Locations arrive: container-image and connector-populated cloud-resource inventories, an image-to-repository link, and typed location items. Harbor and Trivy Operator connectors emit inventories, and the scanned image or resource is recorded on every finding. * 🤖 (Sensei) - Sensei and AI Agent Red Teaming reach general availability. * and much more! Check out the changelog here: https://bit.ly/4rB9VO5

  • Vulnerability management has been priced for enterprises. Whether you're a small team of 2 or have a security team that handles hundreds of developers, vendors do not price for your needs. They price for your size. Starting today, DefectDojo Pro is $100 a month plus 15 cents per finding processed. No seat count, no application count, no sales call. Sign up at cloud.defectdojo.com, connect your scanners, set a monthly spend limit, and pay for what you use. The $100 covers the full Pro feature set: cross-scanner deduplication, EPSS and CISA KEV enrichment, risk-based prioritization, the Triage Engine, Connectors, SSO and RBAC, SLA enforcement, and reporting an assessor will accept. Findings below your minimum severity are dropped before they are counted. Sensei is billed only when you use it: $15 for a remediation pull request, $30 for a threat model. Pre-pay for a year and save 48% or more. Why now? The models attackers will run next year find bugs faster than your team can read the reports. Fixing everything, quickly, should not depend on your headcount. Read the post: https://bit.ly/4jiPNhq

    • No alternative text description for this image
  • You have been lied to about security. Not by the attackers. By the people selling the fix. Charged to find your vulnerabilities. Charged again to see them. Charged a third time to prove you fixed them. That is not a partner. That is a landlord. Today DefectDojo flies a new flag. It is the same mission we've been fighting for the last 10 years but we are no longer just the platform that aggregates your findings, but the platform that identifies and fixes risk. But talk is cheap and seeing is believing. In the last month alone: Threat Intelligence, now generally available, with EPSS and CISA KEV built into prioritization. Reachability. AI Threat Modeling. CSPM. Vulnerability Explorer. Triage Engine. 500+ connectors and parsers. And Sensei, an AI agent that can triage, prioritize, and fix your vulnerabilities in minutes. Your findings are yours. Your data is yours. Your exit is always open. The full story from our CEO: https://buff.ly/7iKV9iP The dojo doors are open. Join the underground.

    • No alternative text description for this image
  • Security vendors have told you cybersecurity is difficult, expensive, and an endless struggle. They're wrong. The backlog doesn't have to be permanent. Security doesn't have to be a struggle. And your tools shouldn't hold your data hostage. Today, we expand the mission of DefectDojo and fight for all teams to bring their vulnerability backlog to zero. Join the underground

  • View organization page for DefectDojo

    2,646 followers

    DefectDojo September 22nd Changelog 🚀 This week, we've released a new update of DefectDojo Pro and Community Edition. Here are the highlights from v3.3.200. 📜 (Compliance) - PCI DSS compliance pack: scope and scope inventory, patch-clock SLAs (6.3.3), targeted risk analyses (12.3.1), quarterly scan and ASV evidence, a vulnerability-management control catalog, and a PCI DSS evidence workbook. 📈 (Dashboards) The Command Center dashboard scene, now the home page for every user. 🎯 (Findings) EPSS and CISA KEV threat-intelligence fields are editable on the Add/Edit Finding form. and much more! Check out the changelog here: https://lnkd.in/e3GPTFKU

Similar pages

Browse jobs